CVE-2020-8636 is a remote code execution vulnerability in OpServices OpMon version 9.3.2. The vulnerability allows an attacker to execute arbitrary code on the affected system remotely. The specific vulnerable function or endpoint is not detailed in the provided information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone Python proof-of-concept exploit for CVE-2020-8636 affecting the Opmon monitoring platform. Structure is minimal: LICENSE, README.md, and a single executable script opmonster.py. The README explains the attack flow and usage, while opmonster.py implements the exploit logic. Core capability: authenticated remote code execution against Opmon by abusing the nettools feature at /opmon/nettools/nettools.php. The exploit leverages attacker-controlled Nmap options to invoke the http-fetch NSE script, causing the target to download a malicious .nse file from an attacker-controlled web server into /tmp. It then triggers a second request to execute that downloaded NSE script via Nmap, which runs an attacker-supplied shell command using Lua os.execute and prints command output back through the web response. Operational flow in code: (1) parse CLI args for target URL, attacker host, attacker port, and command; (2) generate a random .nse filename; (3) write a malicious NSE/Lua payload locally; (4) send POST request to /opmon/nettools/nettools.php with crafted host and nmap_options parameters to fetch the script from the attacker server; (5) check response text for success/failure strings such as "Successfully Downloaded" and "Failed to resolve"; (6) send a second POST request to the same endpoint to execute /tmp/<random>.nse; (7) parse returned HTML and print command output; (8) remove local .nse artifacts. The exploit is not merely a detector: it performs full exploitation and command execution. It is operational but basic, with a hardcoded payload pattern and no advanced session handling, authentication workflow, or payload customization beyond the supplied command string. It also disables TLS certificate verification and assumes the vulnerable functionality is reachable and usable. The main fingerprintable target is the Opmon endpoint /opmon/nettools/nettools.php, and the exploit additionally depends on an attacker-hosted HTTP server serving the generated NSE file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.